PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-40192Highpillow: FITS GZIP decompression bomb in PillowCVE-2026-33858Highapache-airflow: Apache Airflow: Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom APICVE-2025-66236Mediumapache-airflow: Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UICVE-2026-1462Highkeras: Keras has an untrusted deserialization vulnerabilityCVE-2026-4810Criticalgoogle-adk: Google Agent Development Kit (ADK) has a Code Injection and Missing Authentication vulnerabilityCVE-2026-6111Lowmetagpt: MetaGPT affected by server-side request forgery in metagpt/utils/common.pyCVE-2026-6110Mediummetagpt: MetaGPT has an eval injection in metagpt/strategy/tot.pyCVE-2026-6109Lowmetagpt: MetaGPT has an eval injection via a cross-site request forgery attackCVE-2026-5059Criticalaws-mcp: aws-mcp has a Command Injection Remote Code Execution VulnerabilityGHSA-55V6-G8PM-PW4CMediumrembg: rembg server is vulnerable to Server-Side Request Forgery (SSRF) and a weak default CORS configurationCVE-2026-40258Criticalgramps-webapi: gramps-webapi: Zip Slip Path Traversal in Media Archive ImportCVE-2026-40260Mediumpypdf: pypdf: Manipulated XMP metadata entity declarations can exhaust RAMCVE-2026-40086Mediumrembg: Rembg has a Path Traversal via Custom Model LoadingCVE-2026-40178Mediumajenti.plugin.core: ajenti.plugin.core has race conditions in 2FAGHSA-VJ8V-P5VW-M6V5Mediumxrootd: xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." patternCVE-2026-40177Criticalajenti.plugin.core: ajenti.plugin.core has password bypass when 2FA is activatedGHSA-PJJW-68HJ-V9MWLowuv: uv vulnerable to arbitrary file deletion through RECORD entriesCVE-2026-40289Criticalpraisonaiagents: PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessionsCVE-2026-40288Criticalpraisonaiagents: PraisonAI has critical RCE via `type: job` workflow YAMLCVE-2026-40287Highpraisonaiagents: PraisonAI Vulnerable to RCE via Automatic tools.py ImportCVE-2026-40315MediumPraisonAI: PraisonAI: SQLiteConversationStore didn't validate table_prefix when constructing SQL queriesCVE-2026-40162Highbugsink: Bugsink affected by authenticated arbitrary file write in artifactbundle/assembleCVE-2026-40114HighPraisonAI: PraisonAI Vulnerable to Server-Side Request Forgery via Unvalidated webhook_url in Jobs APICVE-2026-56074Mediumpraisonaiagents: PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell CommandsCVE-2026-40160Highpraisonaiagents: PraisonAIAgents: SSRF via unvalidated URL in `web_crawl` httpx fallback

Stop the waste.
Protect your environment with Kodem.